Legal & Privacy
Professional standards for digital stewardship and decision integrity
Jump to Section:
Terms of Use
Last Updated: March 15, 2026
1. Acceptance of Terms
By accessing and using nitaptech.ca ("the Site"), you acknowledge that you have read, understood, and agree to be bound by these Terms of Use. If you do not agree, please discontinue use of the Site immediately.
2. Informational Purposes Only
The content on this Site is provided for general informational and educational purposes only. While Nitap Technologies strives for accuracy, we make no representations or warranties regarding the completeness, reliability, accuracy, or suitability of any information presented.
You acknowledge that: Cybersecurity threats, regulatory requirements, and technology environments change rapidly. Information on this Site may become outdated, and Nitap Technologies has no obligation to update content unless required by law.
3. Professional Services Disclaimer
CRITICAL: This Site does not establish a professional services relationship between you and Nitap Technologies.
Content on this Site, including but not limited to articles, insights, service descriptions, example deliverables, and technical guidance does NOT constitute:
- Professional cybersecurity advice tailored to your specific environment
- Legal, financial, or regulatory compliance advice
- An assessment of your security posture
- An assurance of regulatory compliance
- A recommendation to take or avoid any specific action
For Professional Services: If you require professional cybersecurity, risk management, or compliance services, you must enter into a formal written engagement agreement with Nitap Technologies. Only advice provided under such an agreement constitutes professional services.
3.1 Intellectual Property in Deliverables
While final deliverables (e.g., specific Technology Roadmaps or Audit Checklists) created specifically for a client under a formal agreement may be owned by that client, Nitap Technologies retains all rights, title, and interest in its "Background IP." This includes pre-existing methodologies, templates, prioritization logic, and general cybersecurity frameworks used to produce those deliverables.
4. No Warranties
The Site and all content are provided "as is" and "as available" without warranties of any kind, either express or implied, including but not limited to:
- Warranties of merchantability or fitness for a particular purpose
- Warranties that the Site will be uninterrupted, timely, secure, or error-free
- Warranties regarding the accuracy, reliability, or completeness of content
- Warranties that defects will be corrected
- Warranties regarding third-party links or services
5. Limitation of Liability
To the maximum extent permitted by applicable law:
Nitap Technologies, its principal, employees, contractors, and affiliates shall not be liable for any direct, indirect, incidental, consequential, special, punitive, or exemplary damages arising from or related to:
- Use of or inability to use the Site
- Reliance on any content, advice, or information on the Site
- Security breaches, data loss, or unauthorized access
- Errors, omissions, or inaccuracies in content
- Third-party conduct or content
- Any matter relating to the Site or services
This limitation applies even if Nitap Technologies has been advised of the possibility of such damages.
Maximum Liability: In no event shall Nitap Technologies' total aggregate liability exceed the greater of (a) the total fees paid by you to Nitap Technologies in the twelve (12) months preceding the claim, or (b) CAD $100.
Jurisdictional Limitations: Some jurisdictions do not allow the exclusion or limitation of certain warranties or liabilities. In such jurisdictions, our liability is limited to the maximum extent permitted by law.
5.1 Statutory Limitation Period
Consistent with the Limitation of Actions Act of New Brunswick, any claim or legal proceeding arising out of or related to the use of this Site or our services must be commenced within two (2) years from the date the claimant knew, or ought to have known, of the claim.
5.2 Cybersecurity Disclaimer
You acknowledge that no security assessment or vulnerability management service can ensure 100% protection. Nitap Technologies does not warrant that its services or recommendations will prevent all security breaches, "zero-day" exploits, or unauthorized access by sophisticated third parties.
6. Indemnification
You agree to indemnify, defend, and hold harmless Nitap Technologies, its principal, employees, contractors, and affiliates from and against any and all claims, liabilities, damages, losses, costs, expenses (including reasonable legal fees) arising from:
- Your use or misuse of the Site
- Your violation of these Terms of Use
- Your violation of any rights of another party
- Any content you submit or transmit through the Site
7. Intellectual Property Rights
All content on this Site, including but not limited to text, graphics, logos, images, articles, frameworks, methodologies, and software, is the property of Nitap Technologies or its content suppliers and is protected by Canadian and international copyright, trademark, and other intellectual property laws.
You may:
- View and print content for personal, non-commercial use
- Share links to the Site
You may NOT:
- Reproduce, distribute, modify, or create derivative works without written permission
- Use any content for commercial purposes without a license
- Remove copyright or proprietary notices
- Use automated systems (bots, scrapers) to access the Site
Trademarks: "Nitap Technologies" and associated logos are trademarks of Nitap Technologies. Unauthorized use is prohibited.
8. Third-Party Links and Services
The Site may contain links to third-party websites or services (including Formspree, PostHog, LinkedIn, Credly). Nitap Technologies:
- Does not control or endorse these third-party sites
- Is not responsible for their content, privacy practices, or availability
- Provides links for convenience only
You access third-party sites at your own risk and should review their terms and privacy policies.
9. Use of Insights and Articles
Articles in our "Insights" section represent the personal views, creative reflections, and analysis of the author (Dustyn Martin-Ross) and may draw on publicly available information, lived experience, and professional experience.
These articles:
- Are opinion and analysis, not definitive fact
- Do not necessarily reflect official positions of any organization
- Should not be cited as authoritative sources without independent verification
- May contain forward-looking statements that could prove incorrect
Indigenous Content: When discussing Indigenous communities, data sovereignty, or related topics, we strive for cultural sensitivity and accuracy. However, views expressed are the author's own and may not represent all Indigenous perspectives.
Indigenous Data in Engagements: In formal engagements with Indigenous community clients, we apply our Indigenous Data Sovereignty Framework and incorporate community-specific governance expectations to establish data stewardship commitments in writing.
Data governance, access, use, retention, and transfer are defined by the signed engagement terms, applicable laws, and community protocols. Our methodologies are designed to build internal capacity and transfer knowledge, not to create ongoing dependency or data asymmetry between the community and any outside party, including Nitap Technologies.
10. Contact Form and Communications
Submission of information through our contact form does not:
- Create a client-consultant relationship
- Establish confidentiality or privilege
- Constitute a request for services
- Obligate Nitap Technologies to respond or take any action
By submitting this form, you consent to Nitap Technologies contacting you regarding your specific inquiry. We will not add you to marketing lists without your express opt-in.
Do not submit confidential or sensitive information through the contact form. For confidential communications, contact us to establish a formal engagement with appropriate confidentiality protections.
10.1 Anti-Spam Compliance (CASL)
By submitting our contact form, you provide "implied consent" for Nitap Technologies to contact you regarding your specific inquiry. We will not use your contact information for unrelated marketing purposes or newsletters without your express, "opt-in" consent. You may withdraw consent at any time by contacting [email protected].
11. Changes to Terms
Nitap Technologies reserves the right to modify these Terms of Use at any time without prior notice. Changes are effective immediately upon posting. Your continued use of the Site after changes constitutes acceptance of the modified terms.
12. Dispute Resolution and Governing Law
Good-Faith Negotiation: Before initiating any formal legal proceeding, both parties agree to attempt to resolve any dispute through good-faith negotiation. Either party may initiate this process by providing written notice to the other describing the nature of the dispute and the relief sought. The parties shall have 30 days from the date of such notice to negotiate in good faith.
Mediation: If the dispute is not resolved through negotiation within 30 days, either party may refer the matter to non-binding mediation administered by a mutually agreed-upon mediator in Fredericton, New Brunswick, before pursuing litigation. The costs of mediation shall be shared equally unless otherwise agreed.
Governing Law: These Terms of Use are governed by the laws of the Province of New Brunswick and the federal laws of Canada applicable therein, without regard to conflict of law principles.
Jurisdiction: If a dispute is not resolved through negotiation or mediation, it shall be subject to the exclusive jurisdiction of the courts of New Brunswick, Canada.
13. Severability
If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
14. Force Majeure
Nitap Technologies shall not be liable for any failure or delay in performance arising from causes beyond our reasonable control, including but not limited to acts of God, natural disasters, pandemic, war, terrorism, government restrictions, internet or telecommunications outages, cyberattacks on third-party infrastructure, or other events outside our reasonable control. Obligations affected by such events will be suspended for the duration of the event.
15. Waiver
No failure or delay by Nitap Technologies in exercising any right, remedy, or privilege under these Terms of Use shall operate as a waiver of that right, remedy, or privilege. A waiver of any breach or default shall not be treated as a waiver of any subsequent breach or default of the same or any other provision.
16. Entire Agreement
These Terms of Use, together with the Privacy Policy and any other legal notices published by Nitap Technologies on this Site, constitute the entire agreement between you and Nitap Technologies regarding your use of this Site. They supersede all prior agreements, representations, and understandings between you and Nitap Technologies relating to the subject matter herein.
Privacy Policy
Effective Date: June 22, 2026
1. Commitment to Privacy and Stewardship
Rooted in our value of stewardship, Nitap Technologies treats your personal information with the highest level of accountability and respect. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
Indigenous Data Governance: When engaged by or on behalf of First Nations, Métis, or Inuit communities, Nitap Technologies applies its Indigenous Data Sovereignty Framework and acknowledges OCAP® principles (Ownership, Control, Access, and Possession), as established by the First Nations Information Governance Centre (FNIGC), as a key reference point where relevant. In practice, this means:
- Community Governance: Data governance for each engagement is defined collaboratively with the community and documented in formal engagement terms.
- Purpose Limitation: Nitap Technologies does not repurpose or disclose community data outside the agreed scope without explicit, documented authorization.
- Access and Stewardship: Access, stewardship responsibilities, and handling controls are established in writing to reflect community expectations and legal requirements.
- Control in Practice: Where technically and operationally feasible, implementation approaches are selected to support community-directed control over data.
2. Information We Collect
2.1 Information You Provide Directly
Contact Forms: When you submit our contact form, we collect:
- Name
- Email address
- Organization name (optional)
- Message content
Purpose: To respond to your inquiries and provide requested information about our services.
Legal Basis: Consent (implied by form submission) and legitimate business interests.
2.2 Information Collected Automatically
Analytics Data: We use PostHog (EU) to understand how visitors interact with our Site. This may include:
- Pages visited and time spent
- Click patterns and scroll behaviour
- Device type, browser, and screen resolution
- General geographic location (city/region, not precise location)
- Referral source (how you found our site)
Purpose: To improve user experience, optimize content, and understand visitor needs.
Data Type: Usage data including page views, click events, and interaction logs. PostHog EU processes all data within the European Union. We do not use this data to identify individual users. PostHog applies its own data handling practices as described in their privacy policy.
2.3 Information We Do NOT Collect
- Payment information (we do not process payments through the Site)
- Social insurance numbers or government IDs
- Health information
- Precise geolocation data
- Biometric data
3. How We Use Your Information
We use collected information ONLY for the following purposes:
- Responding to inquiries submitted through our contact form
- Providing information about our services
- Improving website functionality and user experience
- Analyzing site traffic and visitor behaviour (anonymized)
- Complying with legal obligations
We do NOT:
- Sell or rent your personal information to third parties
- Use your information for marketing without explicit consent
- Share your information with third parties except as described in this policy
4. Third-Party Service Providers
We use trusted third-party services to operate our Site. These providers have access to your information only to perform specific tasks on our behalf and are obligated to protect it:
4.1 Formspree (Contact Form Processing)
- Purpose: Manages contact form submissions and delivers inquiries to our email
- Data Shared: Name, email, organization, message content
- Privacy Policy: https://formspree.io/legal/privacy-policy/
- Location: United States (data transferred outside Canada)
4.2 PostHog (Analytics)
- Purpose: Provides website analytics, event tracking, and visitor behaviour insights
- Data Shared: Page views, click events, and interaction data (see Section 2.2)
- Privacy Policy: https://posthog.com/privacy
- Location: European Union (EU region. Data does not leave the EU.)
4.3 Cloudflare (Web Hosting/CDN)
- Purpose: Provides website hosting, security, and content delivery
- Data Shared: IP addresses, request headers (technical data)
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
- Location: Distributed globally with data centers including Canada
4.4 MailerLite (Email Newsletter)
- Purpose: Delivers newsletter and article update emails to subscribers who opt in via the Insights page
- Data Shared: Name (optional) and email address of newsletter subscribers
- Privacy Policy: https://www.mailerlite.com/legal/privacy-policy
- Location: United States (Some of its data processed under GDPR)
5. Data Retention
Contact Form Submissions: Retained for 24 months from last contact, or until you request deletion, whichever comes first.
Analytics Data: Retained by PostHog EU for up to 12 months, consistent with our account settings.
Right to Deletion: You may request deletion of your information at any time (see Section 9).
6. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your information from unauthorized access, disclosure, alteration, or destruction, including:
- Encrypted data transmission (HTTPS/SSL)
- Secure third-party service providers with appropriate security measures
- Limited access to personal information (only personnel who need it)
- Regular security reviews
However: No method of electronic transmission or storage is 100% secure. Nitap Technologies cannot ensure absolute security and is not liable for breaches resulting from causes beyond our reasonable control.
7. International Data Transfers
Our contact form provider (Formspree) transfers form submission data to the United States. PostHog processes analytics data exclusively within the European Union. By using our Site, you consent to data transfers as described. We ensure our service providers maintain appropriate safeguards for transferred data.
8. Cookies and Tracking Technologies
What Are Cookies: Small text files stored on your device by your web browser.
Cookies We Use:
- Essential Cookies: Required for Site functionality (e.g., security, session management)
- Analytics Cookies: PostHog cookies for traffic analysis and event tracking
Managing Cookies: You can control cookies through your browser settings. Note that disabling cookies may affect Site functionality.
Do Not Track and Global Privacy Control: Our Site responds to supported browser privacy signals, including "Do Not Track" and Global Privacy Control, by disabling analytics tracking when those signals are detected.
9. Your Privacy Rights
Under PIPEDA and applicable provincial laws, you have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your information (subject to legal retention requirements)
- Withdraw Consent: Withdraw consent for collection, use, or disclosure of your information (may affect our ability to provide services)
- Complaint: Lodge a complaint with the Office of the Privacy Commissioner of Canada if you believe we have violated your privacy rights
To Exercise Your Rights: Contact us at [email protected] with "Privacy Rights Request" in the subject line. We will respond within 30 days.
10. Children's Privacy
Our Site is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.
11. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will post the updated policy on this page with a revised "Effective Date."
Material Changes: For significant changes affecting your rights, we will provide additional notice (e.g., email notification if we have your contact information).
12. Contact Information
For privacy-related questions, concerns, or rights requests:
Email: [email protected]
Subject Line: Privacy Inquiry
Mailing Address: Nitap Technologies, Fredericton, New Brunswick, Canada
Privacy Officer: Dustyn Martin-Ross, Principal Consultant
13. Data Breach Notification
In the event of a breach of security safeguards involving your personal information that poses a real risk of significant harm to you, Nitap Technologies will:
- Notify you directly as soon as feasible after the breach is identified, in accordance with PIPEDA's breach of security safeguards requirements
- Report the breach to the Office of the Privacy Commissioner of Canada
- Maintain a record of all breaches involving personal information for a minimum of 24 months
Notifications will describe the nature of the breach, the personal information involved, steps Nitap Technologies has taken or will take to mitigate harm, and steps you may take to reduce your own risk. To report a suspected breach or vulnerability involving your data, contact [email protected] with "Data Breach" in the subject line.
Accessibility Statement
Last Updated: April 10, 2026
Nitap Technologies is committed to ensuring digital accessibility for people of all abilities. We strive to meet the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA standard and to align with the principles of the Accessible Canada Act (S.C. 2019, c. 10), which calls for a barrier-free Canada by January 1, 2040.
Applicable Standards
- WCAG 2.1 Level AA: Our target conformance standard for web content
- Accessible Canada Act (ACA): Federal framework guiding our approach to identifying and removing barriers
Current Accessibility Features
- Semantic HTML structure with appropriate landmark regions
- Alt text for meaningful images
- Keyboard navigation support throughout the Site
- Sufficient color contrast ratios for body text and interactive elements
- Readable font sizes with support for browser-based text scaling
- Mobile-responsive design
- Skip-to-main-content navigation for screen reader and keyboard users
Known Limitations
We acknowledge the following areas where our Site may not yet fully meet WCAG 2.1 Level AA:
- Some interactive components may not fully communicate state changes to assistive technologies
- Third-party embedded content (e.g., external links, contact form) is subject to the accessibility practices of those providers
We are actively working to address these limitations. Our goal is to reach full WCAG 2.1 Level AA conformance by December 31, 2026.
Feedback and Assistance
If you encounter an accessibility barrier on our Site, please contact us:
Email: [email protected]
Subject Line: Accessibility
We will acknowledge your message within 5 business days and work to provide the requested information in an accessible alternative format, or address the barrier as quickly as practicable.